What Is a "Laptop Farm," and How Does a Company Laptop End Up in One?

TL;DR: A "laptop farm" is a house or apartment, usually rented by a paid U.S.-based facilitator, where dozens of company-issued laptops sit racked up and running remote-access software so that overseas workers — often North Korean IT operatives — can log in and appear to be physically working from a legitimate U.S. address. Your company's laptop ends up there when a "remote hire" who passed your interviews ships their onboarding equipment to an address that isn't actually where they live or work. DOJ and Microsoft-led actions have dismantled 29 such laptop farms (roughly 200 computers) as of their most recent enforcement wave, and one facilitator was sentenced to 8.5 years over a $17 million scheme.

The claim

Laptop farms are the physical infrastructure behind the North Korean fake IT worker scheme — and interview proctoring alone doesn't stop them. Proctoring verifies who's on the interview call; a laptop farm defeats the next step, where the actual work gets done by someone other than the person who was hired.

The evidence

The scheme works in stages. First, an operative (often a North Korean IT worker using a stolen or fabricated U.S. identity) applies for and lands a remote developer, IT support, or engineering role — sometimes passing interview stages through coached responses or a proxy interviewee. Once hired, the "employee" asks for their company laptop to be shipped to a U.S. address that is, in reality, a facilitator's home or a rented space. The facilitator — frequently a U.S. citizen recruited online and paid a monthly fee — receives the laptop, plugs it in, installs remote-access software (tools like AnyDesk or similar), and the real worker overseas logs in remotely to do the job, keeping the laptop's IP address and login pattern looking domestic.

Multiple facilitators have now been prosecuted. In one widely reported case, a facilitator was sentenced to 8.5 years in prison over a scheme that funneled roughly $17 million to North Korean workers and, through them, to the regime — money the DOJ has tied to funding weapons programs. Joint DOJ and Microsoft enforcement actions have identified and shut down 29 separate laptop farms holding around 200 computers, each one representing multiple "employees" simultaneously defrauding different companies.

Interview-stage vs. laptop-farm-stage fraud

StageWhat's being fakedWhat catches it
Sourcing/applicationFabricated identity, AI-written resume, synthetic photoReverse-checking claimed history, warning-sign review during screening
InterviewProxy interviewee, coached answers, deepfaked videoAI interview proctoring — ID-to-selfie match, continuous face verification, second-voice detection
Onboarding/equipment shippingShipping address doesn't match claimed locationAddress verification, IP/geolocation cross-check at first login, requiring in-person or notarized ID pickup for high-trust roles
Day-to-day workSomeone other than the interviewed person does the jobOngoing identity checks at check-ins, VPN/remote-access monitoring, periodic re-verification calls

Step-by-step: reducing your laptop-farm exposure

  1. Verify identity at the interview stage first. A proxy interviewee or deepfake at this stage is the root cause — AI Meeting Proctor's ID match and continuous face verification close this gap before equipment ever ships.
  2. Cross-check the shipping address against the candidate's stated location. A mismatch, a residential address serving multiple "employees," or resistance to a video-verified delivery are all red flags IT/security teams should escalate.
  3. Require a live video check-in on day one, not just a Slack message, to confirm the person receiving and using the laptop is the same person who interviewed.
  4. Monitor for remote-access software (AnyDesk, TeamViewer, similar) running persistently on company-issued devices where it wasn't provisioned by IT.
  5. Watch for behavioral tells post-hire: requests to change payment methods repeatedly, VPN use masking true location, or working hours inconsistent with the claimed time zone.
  6. Report suspected cases. The FBI and DOJ actively investigate these schemes and have public reporting channels — early reporting has led to multiple laptop-farm takedowns.

FAQ

Is a laptop farm always tied to North Korea specifically? The publicized enforcement cases to date center on North Korean IT worker schemes, since sanctions evasion and weapons-program funding are the primary DOJ concern, but the underlying mechanic — a domestic facilitator running devices for an overseas worker — could theoretically be used by other fraud rings.

Can AI interview proctoring alone prevent a laptop farm situation? It closes the interview-stage gap — stopping proxy interviewees and deepfakes from getting hired in the first place — but the shipping and onboarding stage needs separate address verification and IT monitoring controls.

What industries are most targeted? Remote software engineering, IT support, and blockchain/crypto development roles have been the most heavily targeted, since they combine high pay, minimal in-person contact, and access to sensitive systems.

How much money has this scheme generated for North Korea overall? Individual prosecuted cases have involved millions of dollars each; U.S. officials have described the broader scheme, across many companies and facilitators, as generating hundreds of millions of dollars over several years.

What should HR do if it suspects a current employee is part of this scheme? Loop in IT security and legal immediately, preserve access logs and shipping records, and avoid tipping off the employee before evidence is secured — these cases are typically referred to the FBI once internal evidence supports it.

By Pinal Dave Last updated: August 4, 2026